Hi, I was hoping someone can help me with some information. I have a secedit command that is calling an .inf file. I am trying to convert some of this stuff to a GPO. In the [event audit] portion I am trying to decipher the logging levels e.g(auditobjectaccess = 3) the logging levels range from 0 to 3, can someone direct me to here i can discern what these logging levels represent? Thanks in advance.

Open MMC and add teh Grpoup Policy snapin on any machine and set it to use the LocalMachine. This willdsiplay the correct current settings. The ones you are looking at may not be correct. You willalso see that the settings are already decoded as they will need to be used in Group Policy. GP Edit converts the older policy settings whn it finds them. Tisis not one but others have been updated.

If you set object access to 3 you will slow the machine to a crawl because every object that gts accesses will generate an audit.

AuditPolicyChange should be set to 3 because it will tell you when someone is trying to break in.

Auditing every access to DS will also slow the machine down.

These settings for object and DS are for diagnostic purposes and should only be used when necessary.

Okay, Thanks for your help. but honestly these are not help desk question. I would challenge you to find any help desk personnel that would know this..

However thanks for your help. I appreciate it.!

Anyone trained in Windows Administration would know the answers to these questions. Microsoft support has trained people. Certification requires that you either know these answers or you know how to find the answers in the documentation.

I will admint that evensome trained admins try to use secedit to updte policy. I have not yet fifured out why although it is the only way to so certain things in a workgroup although GP can be dsitributed in a workgroup too.

DOn't worry about it. I just donm't want us to wear out teh forum on things that are not about scripting. Believe me. The guys in the Group Policy forum can answer these questions even better than I can.

Good lucjk and stay away from secedit. Use Local POlicy MMC snap-in and you will not have these issues. SECedit doe not deal with any of this gracefully.